git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Teams of people using signed commits...

From
MBMagnus Bäck <baeck@google.com>
Date
Jun 14, 2013, 19:25 UTC
Message-ID
<20130614192526.GA25486@google.com>
In-Reply-To
<CABQymNKuwiOz-MQuM12fWSgBvBsBrykNYBqPBxCuSuxAC5cZZw@mail.gmail.com>
On Friday, June 14, 2013 at 15:02 EDT,
     Eric Fleischman <efleischman@gmail.com> wrote:
> We're very interested in using signed commits but are struggling to
> figure out how to use it in the real world. Would love some advice
> from those who know more.

What do you expect to gain from using signed commits? I'm not saying they don't have a place, but depending on why you find them attractive there might be alternatives. For example, won't signed tags do?

Show 5 quoted lines
> We think we know how to deal with signed commits & auto-reject such
> commits at build time, as well as clean up. But we're worried that
> folks won't sign on the way in accidentally. We don't know of a good
> way to force the team to always sign commits yet, especially as they
> get new machines and what hav eyou.

Hooks? A pre-commit hook that runs on the machine and/or a server-side hook (pre-receive or update?) should be able to enforce this. Well, a client hook is trivially bypassed so it would just be useful against mistakes and forgetfullness.

> Is there a way to add something to the repo config to force, or at
> least default, this?

I don't believe you can configure Git to sign commits by default, but if you control the machine of your machines (assuming a corporate) environment you can set up a template directory for hook distribution. Again, that's only for client hooks that are okay to be circumventable.

[...]
-- 
Magnus Bäck
baeck@google.com
Previous: Eric FleischmanNext: Fredrik Gustafsson
Message 2 of 3 in “Teams of people using signed commits...”
  1. Eric FleischmanJun 14, 2013
  2. Magnus BäckJun 14, 2013
  3. Fredrik GustafssonJun 14, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.